Synchronizing Red Hat Directory Server with Microsoft Active Directory Fails if Entries Have Empty Attribute Values

Solution Unverified - Updated -

Environment

  • Red Hat Enterprise Linux 4

  • Red Hat Enterprise Linux 5

  • Red Hat Directory Server 8 (prior to version 8.2)

  • Red Hat Directory Server 7
  • Microsoft Active Directory
  • LDAP entry (within the scope of the synchronization agreement) that contains an empty attribute value

Issue

  • Synchronization from Red Hat Directory Server to Active Directory fails with the error message "Error in attribute conversion operation"

Resolution

  • Syntax validation was added to Red Hat Directory Server 8.2.  Customers should upgrade to the latest version.

Root Cause

  • The problem is that an empty attribute value is illegal for most LDAP syntaxes.  Versions of RHDS prior to 8.2 do not perform syntax validation; empty attribute values are allowed for all syntaxes in these versions. 

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.